← RETURN TO CITADEL

♜ CLOUDFLARE TUNNEL

PUBLIC ACCESS · ZERO PORT FORWARDING · SYSTEMD SERVICE · SECURE ROUTING

STATUS: ACTIVE

PROJECT SNAPSHOT

STARTED

May 2026

STATUS

Active and operational

TUNNEL

citadel-tunnel

TECH STACK

Cloudflare · cloudflared · Apache · Ubuntu · systemd

PROJECT OVERVIEW

The Cloudflare Tunnel project provides public access to The Citadel without traditional router port forwarding. Instead of exposing inbound ports directly to the internet, the Ubuntu host maintains an outbound tunnel connection to Cloudflare.

This allows rootandrook.com to reach the Citadel platform while keeping the local network architecture cleaner and reducing direct exposure of the home lab environment.

TRAFFIC FLOW

Visitor

rootandrook.com

Cloudflare Edge

Cloudflare Tunnel

Ubuntu Host

Apache on Port 80

The Citadel Website

CURRENT CONFIGURATION

SECURITY VALUE

Cloudflare Tunnel avoids traditional inbound router port forwarding while still allowing the Citadel platform to be publicly accessible. This creates a cleaner exposure model for a home lab and places Cloudflare in front of the public endpoint.

COMMAND AREAS PRACTICED

cloudflared tunnel list
systemctl status cloudflared --no-pager
cloudflared version
apt policy cloudflared
sudo apt update
sudo apt install cloudflared

MAINTENANCE ACTIVITY

LESSONS LEARNED

NEXT OBJECTIVES

Citadel Project Switchboard

Module Links Active
01 //
Linux Hardening
SSH, UFW, Fail2Ban, permissions, and operating guardrails.
Open Module →
02 //
Cloudflare Tunnel
Secure public access without exposing the VM directly.
Open Module →
03 //
Docker Lab
Containerization practice, deployment notes, and recovery workflows.
Open Module →
04 //
Auth Monitor
Authentication visibility and login monitoring foundation.
Open Module →
05 //
SIEM Sandbox
Security monitoring lab and future detection engineering space.
Open Module →
06 //
Auto Deploy
Automation pipeline for future repeatable deployment workflows.
Open Module →
07 //
Odysseus
AI assistant prototype, RAG memory core, and hardware roadmap.
Open Module →
08 //
B-MAK
Private operations case study using sanitized public-safe data only.
Open Module →